cve-2026-70734

HIGH CVSS 7.4 nvd
Description

Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Autonomous Health Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H).

Timeline
Published
2026-08-18
Last Modified
2026-08-26
CVSS Details
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
Affected Products
  • oracle autonomous_health_framework
Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 7.4 HIGH CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H 1.1 5.8 secalert_us@oracle.com
CPE configurations
OR
CPE Version range Vulnerable
cpe:2.3:a:oracle:autonomous_health_framework:*:*:*:*:*:*:*:* >= 26.0.0, <= 26.1.0 yes
cpe:2.3:a:oracle:autonomous_health_framework:26.2.0:*:*:*:*:*:*:* — yes
cpe:2.3:a:oracle:autonomous_health_framework:26.3.1:*:*:*:*:*:*:* — yes
cpe:2.3:a:oracle:autonomous_health_framework:26.5.0:*:*:*:*:*:*:* — yes
cpe:2.3:a:oracle:autonomous_health_framework:26.5.2:*:*:*:*:*:*:* — yes
NVD metadata
NVD status
Analyzed
Source identifier
secalert_us@oracle.com
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 7.4,
  "datePublished": "2026-08-18T21:17:26.087",
  "dateUpdated": "2026-08-26T20:17:36.590",
  "description": "Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer).  Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and  26.5.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Autonomous Health Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H).",
  "id": "CVE-2026-70734",
  "raw": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Oracle Autonomous Health Framework",
            "vendor": "Oracle Corporation",
            "versions": [
              {
                "lessThanOrEqual": "26.1.0",
                "status": "affected",
                "version": "26",
                "versionType": "custom"
              },
              {
                "status": "affected",
                "version": "26.2.0",
                "versionType": "semver"
              },
              {
                "status": "affected",
                "version": "26.3.1",
                "versionType": "semver"
              },
              {
                "status": "affected",
                "version": "26.5.0",
                "versionType": "semver"
              },
              {
                "status": "affected",
                "version": "26.5.2",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "secalert_us@oracle.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:oracle:autonomous_health_framework:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D7D081AC-A127-4564-8C9B-1C0BD844E7F7",
                "versionEndIncluding": "26.1.0",
                "versionStartIncluding": "26.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:oracle:autonomous_health_framework:26.2.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "471170FE-118C-4D4E-AD3D-5A23F9FA9CAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:oracle:autonomous_health_framework:26.3.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "4B5EF425-C9EB-443C-BF39-FB2750B5EABC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:oracle:autonomous_health_framework:26.5.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "8B4C43E8-2B34-4A1E-ADED-A3DB20A9917B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:oracle:autonomous_health_framework:26.5.2:*:*:*:*:*:*:*",
                "matchCriteriaId": "9C94B05D-4E5A-4560-ACF0-7F167951F8E8",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer).  Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and  26.5.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Autonomous Health Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H)."
      }
    ],
    "id": "CVE-2026-70734",
    "lastModified": "2026-08-26T20:17:36.590",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.1,
          "impactScore": 5.8,
          "source": "secalert_us@oracle.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-70734",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-25T15:00:42.952060Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-18T21:17:26.087",
    "references": [
      {
        "source": "secalert_us@oracle.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.oracle.com/security-alerts/cspuaug2026.html"
      }
    ],
    "sourceIdentifier": "secalert_us@oracle.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  },
  "severity": "HIGH",
  "source": "nvd",
  "title": "Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer)"
}
View JSON API Download JSON